Liquid Web Status · History · Incident #140221

RESOLVED

Security Advisory: Critical WordPress Vulnerability - "Click2Shell"

Minor · Started Sep 22, 2026 · 4:13 PM

  • Duration

    8d 22h 16m

  • Severity

    Minor

  • Detection lead

    —

  • User reports

    —

Summary

Security Advisory: Critical WordPress Vulnerability - "Click2Shell"

This incident is now resolved. All customers are strongly encouraged to confirm the Wordpress version for all of the websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit. For additional information, please refer to the official WordPress security announcements: https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ https://wordpress.org/documentation/wordpress-version/version-7-1-2/


  • Started

    Sep 22, 2026 · 4:13 PM

  • Resolved

    Oct 1, 2026 · 2:29 PM

  • Duration

    8d 22h 16m

  • Severity

    None

Event timeline

How this incident unfolded

  • ◐

    Investigating

    Sep 22 · 4:13 PM Liquid Web

    WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link. Current Status & Hosting Actions Our engineering team is currently assessing our entire hosting fleet and determining next steps. There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress. Recommended Action for Customers We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1. We will continue to monitor the situation closely and provide further updates as new information becomes available.

  • ◆

    Identified

    Sep 23 · 2:36 AM Liquid Web

    Our Engineering team continues to assess and work on the WordPress security vulnerabilities across our hosting fleet. A new critical vulnerability, CVE-2026-87902, has been disclosed. WordPress 7.1.2 includes the security fix for this vulnerability. Recommended Action for Customers We strongly advise all customers managing WordPress installations to update to WordPress version 7.1.2 immediately. We will continue to monitor the situation closely and provide further updates as new information becomes available.

  • ◉

    Monitoring

    Sep 25 · 3:36 PM Liquid Web

    Liquid Web Systems Engineers continue to monitor this situation closely. All Customers are strongly encouraged to confirm that all Wordpress websites they host, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. For additional information, please refer to the official WordPress security announcements: https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ https://wordpress.org/documentation/wordpress-version/version-7-1-2/ If you have any questions or need assistance with the update process, please contact our Support team. You can reach us through the following channels: Live Chat via the Customer Portal: https://my.liquidweb.com/ Email: support@liquidweb.com We appreciate your patience and understanding as we work to secure your services.

  • ✓

    Resolved

    Oct 1 · 2:29 PM Liquid Web

    This incident is now resolved. All customers are strongly encouraged to confirm the Wordpress version for all of the websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit. For additional information, please refer to the official WordPress security announcements: https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ https://wordpress.org/documentation/wordpress-version/version-7-1-2/

Get an email when Liquid Web opens, updates or resolves an incident.

Add it as a dependency monitor. The Free plan includes one.